Mailfence
Mailfence is an encrypted email service that offers OpenPGP based end-to-end encryption and digital signatures.
Score
Notes
Data is not used for targeted advertising
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Citation
Should you close your account, all data will be permanently deleted 30 days after the legal expiration date (i.e. the Belgian law imposes 365 days after account closing). This means that your data will be PERMANENTLY deleted, as opposed to the practice of some major cloud companies which are unable to delete data. We do not delete your account before the legal expiration date because users often ask to reopen their account after having closed it themselves.
Notes
A separate tutorial on how is on their support page: https://kb.mailfence.com/kb/how-can-i-delete-my-account/
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Citation
We do not sell, trade or otherwise transfer to outside parties your personally identifiable information except when forced by Belgian law [...].
Score
Citation
We do not participate nor co-operate with any kind of private or government surveillance or monitoring service. Note that Belgium does not have any equivalent to the US NSL (National Security Letter) and gag order, so we cannot be forced to do something without being allowed to disclose it.
We do not co-operate with the NSA, we do not offer any authority shadow access to our Service.
We also do not directly disclose any information about our users to law enforcement agencies from outside Belgium and it would be illegal for us to do so.
Check our transparency report along with an up-to-date warrant canary.
Notes
The service discloses who they won't share data to, but doesn't mention if and when they will to other parties.
Score
Notes
There are seperate white papers for this:
https://mailfence.com/en/secure-email.jsp
https://mailfence.com/en/end-to-end-encryption.jsp
https://mailfence.com/en/two-factor-authentication.jsp
Score
Citation
Last updated on June 21, 2017.
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Notes
This policy doesn't require the service to disclose data breaches to users
Score
Citation
If we decide to change our privacy policy, we will notify you of the changes.
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Notes
No data is collected from third parties
Score
Citation
The information we collect from you may be used in any of the following ways :
To perform technical checks;
To fulfill legal requests;
To deliver customer service
To process payment transactions.
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Notes
Data isn't used for non-essential purposes
Score
Citation
We collect IP addresses, message-ID's, sender and recipient addresses, subjects, browser versions, countries and timestamps.
When registering, you will be asked to enter an external email address. We send your activation code to this address and use it to communicate with you in case you are unable to access your account.
Incoming and outgoing messages are automatically analysed by our anti-spam, anti-virus and anti-abuse checking routines.
We implement a local instance of Matomo, an open source analytics tool, on the commercial website only (home, registration and subscription pages included) and not within the application itself.
When you pay by credit card we store some of its details.
Team members have signed a confidentiality agreement to protect collected data.
Last Updated
June 24, 2020
Sources
Contributors